发明授权
US09031916B2 Storing log data efficiently while supporting querying to assist in computer network security
有权
有效地存储日志数据,同时支持查询以协助计算机网络安全
- 专利标题: Storing log data efficiently while supporting querying to assist in computer network security
- 专利标题(中): 有效地存储日志数据,同时支持查询以协助计算机网络安全
-
申请号: US11966078申请日: 2007-12-28
-
公开(公告)号: US09031916B2公开(公告)日: 2015-05-12
- 发明人: Wei Huang , Wenting Tang , Christian F. Beedgen
- 申请人: Wei Huang , Wenting Tang , Christian F. Beedgen
- 申请人地址: US TX Houston
- 专利权人: Hewlett-Packard Development Company, L.P.
- 当前专利权人: Hewlett-Packard Development Company, L.P.
- 当前专利权人地址: US TX Houston
- 主分类号: G06F7/00
- IPC分类号: G06F7/00 ; G06F17/00 ; H04L12/24 ; G06F11/34 ; G06F17/30 ; G06F21/55
摘要:
A logging system includes an event receiver and a storage manager. The receiver receives log data, processes it, and outputs a data “chunk.” The manager receives data chunks and stores them so that they can be queried. The receiver includes buffers that store events and a metadata structure that stores metadata about the contents of the buffers. The metadata includes a unique identifier associated with the receiver, the number of events in the buffers, and, for each “field of interest,” a minimum value and a maximum value that reflect the range of values of that field over all of the events in the buffers. A chunk includes the metadata structure and a compressed version of the contents of the buffers. The metadata structure acts as a search index when querying event data. The logging system can be used in conjunction with a security information/event management (SIEM) system.
公开/授权文献
信息查询